Browse Source

SEC-2832: Update request attributes with new CsrfToken

pull/179/head
Stillglade 11 years ago committed by Rob Winch
parent
commit
aa0a5b96ab
  1. 4
      web/src/main/java/org/springframework/security/web/csrf/CsrfAuthenticationStrategy.java

4
web/src/main/java/org/springframework/security/web/csrf/CsrfAuthenticationStrategy.java

@ -56,6 +56,8 @@ public final class CsrfAuthenticationStrategy implements @@ -56,6 +56,8 @@ public final class CsrfAuthenticationStrategy implements
CsrfToken newToken = this.csrfTokenRepository.generateToken(request);
this.csrfTokenRepository.saveToken(null, request, response);
this.csrfTokenRepository.saveToken(newToken, request, response);
request.setAttribute(CsrfToken.class.getName(), newToken);
request.setAttribute(newToken.getParameterName(), newToken);
}
}
}
}

Loading…
Cancel
Save